
TomS Vaptcha Security & Risk Analysis
wordpress.org/plugins/toms-vaptchaGesture captcha —— Easy for human, hard for robots. Protect the login, register, lostpassword and comment forms, support woocommerce, ultimate member, …
Is TomS Vaptcha Safe to Use in 2026?
Generally Safe
Score 85/100TomS Vaptcha has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The toms-vaptcha plugin, version 1.1.2, exhibits a generally strong security posture, characterized by a lack of known historical vulnerabilities and a high degree of proper output escaping. The static analysis reveals a very small attack surface, with no unprotected entry points identified. Furthermore, the absence of critical or high severity taint flows is a positive indicator of secure coding practices concerning data handling and sanitization. The plugin also demonstrates good security awareness by implementing nonce and capability checks for its single identified entry point.
However, there are a couple of areas that warrant attention. The single SQL query present is not using prepared statements, which could pose a risk if sensitive data were involved and the query was constructed with user-supplied input, although the taint analysis did not reveal any unsanitized paths for this query. Additionally, the plugin performs one file operation and one external HTTP request. While not inherently insecure, these operations can introduce vulnerabilities if not handled with extreme care, especially concerning input validation and the origin of the external request.
In conclusion, toms-vaptcha v1.1.2 appears to be a relatively secure plugin with a clean vulnerability history and a well-controlled attack surface. The primary area for improvement lies in adopting prepared statements for its SQL queries to further mitigate potential risks. The limited scope of file operations and external requests, combined with the absence of significant taint flow issues, suggests a low overall risk profile.
Key Concerns
- Raw SQL query without prepared statements
TomS Vaptcha Security Vulnerabilities
TomS Vaptcha Release Timeline
TomS Vaptcha Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TomS Vaptcha Attack Surface
Shortcodes 1
WordPress Hooks 41
Maintenance & Trust
TomS Vaptcha Maintenance & Trust
Maintenance Signals
Community Trust
TomS Vaptcha Alternatives
TomS reCAPTCHA
toms-recaptcha
Integrated Google ReCaptcha for WordPress.Protect the login, register, lostpassword and comment forms. Support Woocommerce, Ultimate Member and more p …
SiteGuard WP Plugin
siteguard
SiteGurad WP Plugin is the plugin specialized for the protection against the attack to the management page and login.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
Really Simple CAPTCHA
really-simple-captcha
Really Simple CAPTCHA is a CAPTCHA module intended to be called from other plugins. It is originally created for my Contact Form 7 plugin.
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
TomS Vaptcha Developer Profile
7 plugins · 1K total installs
How We Detect TomS Vaptcha
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toms-vaptcha/assets/css/admin.css/wp-content/plugins/toms-vaptcha/assets/css/tomswp.cssHTML / DOM Fingerprints
toms-menu-itemtoms-wp-headertoms-menu-title-texttoms-dashboardtoms-menu-texttoms-wp-dashboardtoms-headertoms-logo+12 moredata-toms-wp-dashboarddata-toms-headerdata-toms-logodata-toms-header-textdata-toms-current-activateddata-toms-items+9 morewindow.toms_objectwindow.toms_json